osu!.exe

osu!

Dean Herbert

This is the uninstaller utility registered in the Windows Control Panel for the program osu! by ppy Pty Ltd. The file has been seen being downloaded from m2.ppy.sh and multiple other hosts.
Publisher:
ppy  (signed by Dean Herbert)

Product:
osu!

Version:
1.3.3.7

MD5:
5f0e8300089e101d00487e9d786e1e6e

SHA-1:
a1becd6d4fcca1f6f136054a0941c5c2d07e4b0c

SHA-256:
2caa37a1bf7ad6e2bf5c5ebbeaf77f58f844ba04e7faedf13e40d7ed65cb7678

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 12:29:11 PM UTC  (today)

File size:
3.1 MB (3,283,016 bytes)

Product version:
1.3.3.7

Copyright:
ppy 2007-2015

Original file name:
osu!.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/27/2012 7:00:00 PM

Valid to:
9/28/2015 6:59:59 PM

Subject:
CN=Dean Herbert, O=Dean Herbert, STREET=41 Gregory Street, STREET=Wembley, L=Perth, S=WA, PostalCode=6014, C=AU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FD15503D4AF404C84200F5CCC3C99380

File PE Metadata
Compilation timestamp:
8/31/2015 10:44:05 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:0MRxpYbheLV18lt8i9iHt/Zcpa0SlyQFFOMl8CSeLYpYaa:0MRxpYbhUV18lP9iHt/ZcpvS1C5e

Entry address:
0x1F14AE

Entry point:
FF, 25, 9E, 14, 5F, 00, 00, 00, 5F, 43, 6F, 72, 45, 78, 65, 4D, 61, 69, 6E, 00, 6D, 73, 63, 6F, 72, 65, 65, 2E, 64, 6C, 6C, 00, 0D, C8, 02, 00, 7B, 7A, 7D, 01, 00, 98, 03, 00, FD, C7, 02, 00, 00, 98, 03, 00, EC, BD, 09, 98, 25, 55, 79, 30, DC, 03, AE, 6C, 31, 04, 23, 22, D1, 6A, 0C, 76, B7, F4, 3E, 33, CC, D0, 52, C0, ED, 6D, A6, A1, 37, FA, F6, CC, 88, 8C, 36, 75, EF, AD, DB, 5D, CC, BD, 55, 97, AA, BA, DD, 73, 21, 88, 2B, FE, 2E, A0, B8, 7D, 18, F7, E8, E7, 6E, 8C, 06, 05, 89, 51, 23, 44, 8D, 71, 37, C1...
 
[+]

Entropy:
6.3946

Code size:
2.9 MB (3,078,656 bytes)

Program Uninstaller
Program name:
osu!

Display publisher:
ppy Pty Ltd

Display version:
latest

Uninstall string:
C:\Program Files (x86)\osu!\osu!.exe -uninstall


The file osu!.exe has been discovered within the following program.

osu!  by peppy
osu.ppy.sh
About 1% of users remove it
 
Powered by Should I Remove It?

The file osu!.exe has been seen being distributed by the following 6 URLs.

Scan osu!.exe - Powered by Reason Core Security